#!/bin/bash
set -e

# 验证私钥
openssl pkey -pubout -in foo.key | openssl sha256

# 验证csr
openssl req -pubkey -in foo.csr -noout | openssl sha256

# 验证证书
openssl x509 -pubkey -in foo.crt -noout | openssl sha256

# 验证证书
openssl verify -CAfile root.crt foo.crt

